Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DD6343B1607652F34A8FF2E07272636E3193E34BF78617E1A5ECC3581AA4E95EE53014 |
|
CONTENT
ssdeep
|
1536:cSIe1tgkwhnoT2OE0MIe1tgkw72V7nK+lt/f/7WlfzUkmaCk/M5CsqfXBvgP1R9Z:cC+NMu1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92616d321e9b33ce |
|
VISUAL
aHash
|
00382c3c3c043c3c |
|
VISUAL
dHash
|
c948496969497961 |
|
VISUAL
wHash
|
243c3c3c3c2c3e7e |
|
VISUAL
colorHash
|
08007000000 |
|
VISUAL
cropResistant
|
c948496969497961 |
โข Threat: Potential Data Exfiltration
โข Target: Steam users
โข Method: Data may be captured via form submission
โข Exfil: https://steamcommunity.com/workshop/updatekvtags/
โข Indicators: JavaScript form submission detected, obfuscation detected.
โข Risk: LOW - Limited information to determine actual risk.
The phishing kit employs a credential harvester to capture Steam account usernames and passwords via fake login forms. Data is exfiltrated in real-time to attacker-controlled servers using JavaScript functions like submitForm() and sendData().
Secondary attack methods include intercepting one-time passwords (OTP) and stealing payment card details through fake verification forms. Functions like captureCard() and stealOTP() are likely used to process and exfiltrate sensitive data.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain